{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:09e3961b-bcc9-5378-bbbd-adbc3ef6b13e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-client",
      "version": "9.4.50.v20221201-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3da617ff-4ed4-5dc6-9398-e368482eaede",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25f8bb01-3b92-5a08-951f-0c36d92fd151",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4179fd7b-dd8f-5ed4-bd69-8715027bfe22",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d72c8f2-f551-563f-a3c1-3aef9f6984c7",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738fde37-c059-555f-820c-0a419f756b18",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16ae790b-a6dd-53be-a9d2-7f3fbcc8809c",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e9f267-e29a-5c42-9d0c-4fb5cf14e3c8",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b66303-f79c-5915-9ba3-cbb10ad28260",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37878862-d0ff-58a2-9103-0579f275d47f",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0ee824-eaca-5ed9-915a-0c9e293ab015",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f39198-3647-5987-be63-d057be83f4b7",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0818fdd6-f4b3-5571-ae05-dc26ca25e3aa",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3cc9b1-5c4c-5fe9-862b-0c55072f95b9",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4625f833-91ef-5886-8ca6-1c50794ec62d",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f81192e-ffc7-5757-977e-a2ceb005e9a7",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93874dfb-d40e-5435-93f5-2e85606a36ff",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7819b606-0e76-5723-8be9-3d75646c0cf2",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de717d32-9d43-53a1-a2fb-6953af939862",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab71135b-ae6c-5d7f-b971-5a754f81c4a1",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b88ac9d-b79e-5cbb-881c-d6f7108ddbc3",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1fbcd4f-7392-5bb9-adfb-206c841427e7",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d7f63b-c8d8-55fd-ba5f-8e7b6646fc9b",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64242501-fb7f-53b5-89ca-526e92e6a269",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73a8115-8cdd-5099-88f2-d57925e00695",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99991e98-b209-53ce-8f47-327c6bee070f",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb3d4e5-a7cb-5c31-8d86-87ca89b841ea",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72cc055b-d041-589a-8a0d-ca4276af73c0",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.1 of org.eclipse.jetty:jetty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-client@9.4.50.v20221201-tuxcare.1"
    }
  ]
}